Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

Release Date: 06th of October 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations and individuals that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2010-3962 is a use-after-free / uninitialized memory corruption vulnerability in Microsoft Internet Explorer (IE) that was disclosed in November 2010. The vulnerability allows a specially crafted web page to trigger improper handling of an object (via CSS token sequences and the clip attribute), leading to memory corruption and potential remote code execution in the context of the user viewing the page.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2010-3962
  3. https://learn.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-090